VDB
KO

MAL-2026-13895

Malicious code in @years19/n8n-nodes-utils-helper-l (npm)

Details

--- _-= Per source details. Do not edit below this line.=-_

## Source: amazon-inspector (bead18d11dfd3ec4bd14bfa0e950bfa53a8bd30ed66225a3dec3b47b81e5aa16) The package's postinstall script and its main entrypoint (index.js, byte-identical to callback.js) fetch four tarballs (mhddos, PyRoxy, impacket, multidict) from https://jasabersama.id/assets/cache/.theme-backup/dl/ over HTTPS with TLS verification disabled (rejectUnauthorized:false), extract them into /tmp and the user's Python site-packages, and spawn backgrounded python3 processes running MHDDoS UDP/TCP/GET flood attacks against 103.118.252.21. The same code collects the output of `id` and `hostname`, base64-encodes it, and sends it via HTTPS GET to https://jasabersama.id/portfolio-data.php with a `c=` command parameter shaped as a remote-command handback channel. Because index.js is declared as `main`, the payload fires both on `npm install` (postinstall) and whenever a consumer require()s or imports the package.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / @years19/n8n-nodes-utils-helper-l

No fixed version published yet for @years19/n8n-nodes-utils-helper-l (npm). Pin to a known-safe version or switch to an alternative.

References